Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-2922


The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.


Published

2015-05-27T10:59:06.987

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 3.3 (LOW)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

6.5

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-17

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System linux linux_kernel ≤ 3.19.5 Yes
Operating System fedoraproject fedora 20 Yes
Operating System fedoraproject fedora 21 Yes
Operating System fedoraproject fedora 22 Yes
Operating System oracle linux 5.0 Yes
Operating System oracle solaris 11.3 Yes
Operating System redhat enterprise_mrg 2.5 Yes
Operating System debian debian_linux 7.0 Yes
Operating System debian debian_linux 8.0 Yes

References